{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:404c463f-f2c4-590a-95ab-a106e2b20e00",
  "version": 1,
  "metadata": {
    "tools": [
      {
        "name": "tuxcare-vex-generator",
        "version": "1.0.0"
      }
    ]
  },
  "components": [
    {
      "bom-ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4",
      "type": "library",
      "group": "org.springframework",
      "name": "spring-tx",
      "version": "4.3.30.RELEASE-tuxcare.4",
      "purl": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
    }
  ],
  "vulnerabilities": [
    {
      "bom-ref": "urn:uuid:587e8edb-0acf-5e8a-a3d6-7776d390b1b5",
      "id": "CVE-2016-1000027",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cb8bd546-f74e-5ac3-8e8d-7df3b53096f0",
      "id": "CVE-2020-5397",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2020-5397 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e5370e29-b48c-5108-9d03-a40e55985a75",
      "id": "CVE-2020-5421",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2020-5421 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx. Version 4.3.30.RELEASE is not affected by CVE-2020-5421: the security fix is already present in the target branch. Momus prerequisite check: \"Patches already applied: 6327c60912cd80120040c8c16c3731d8bf6c19f6\". No backport needed."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2bfe9080-2802-5c66-acb6-836ced39b757",
      "id": "CVE-2021-22060",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2021-22060 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b796a5ff-888a-501d-b24a-cec347befa52",
      "id": "CVE-2021-22096",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22096 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx. CVE-2021-22096 fix already exists in commit 4895b739b3e5fea63ecb01ac867c136add560cf6"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:63c4b86f-15f8-533f-9bb1-8906d050c046",
      "id": "CVE-2021-22118",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2021-22118 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx. Version 4.3.30.RELEASE is not vulnerable. Summary: Target repository is Spring Framework 4.3.30.RELEASE-tuxcare.2, which predates the introduction of WebFlux. The vulnerable code (reactive multipart handling with predictable temp directories) does not exist in this version. CVE-2021-22118 specifically affects WebFlux applications in Spring Framework 5.2.x prior to 5.2.15 and 5.3.x prior to 5.3.7. WebFlux was introduced in Spring Framework 5.0, and the vulnerable multipart han [terminalized not_affected from patch_application_manual/not_vulnerable]"
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:cddcb1d3-35f2-5161-8d06-3de514b6e2c5",
      "id": "CVE-2022-22950",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b4a2719f-585b-58ac-9f3c-40e10323b14c",
      "id": "CVE-2022-22965",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1881e6f1-f259-5533-86b1-5cee3f7c1d26",
      "id": "CVE-2022-22968",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22968 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d84187d3-1fc8-58b3-bc17-4cf88c8fada9",
      "id": "CVE-2022-22970",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22970 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:71574e39-8430-5904-8a56-72d91d361e34",
      "id": "CVE-2022-22971",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22971 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:caedc8a2-48b5-53e4-bbaf-33f2e6976b94",
      "id": "CVE-2023-20863",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2023-20863 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ef15e70c-dbc6-585c-be68-8da9977f05e1",
      "id": "CVE-2024-22243",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22243 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b645a1c6-67a2-5c50-8a1b-f82bdbdeded6",
      "id": "CVE-2024-22259",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22259 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6fcb2edc-68df-553f-9909-7dcaf812ae37",
      "id": "CVE-2024-22262",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-22262 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ffd91d11-bea9-5af3-a79b-dc13cd2125f7",
      "id": "CVE-2024-38808",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38808 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:46e076d9-21fe-55da-ae8a-136983db773c",
      "id": "CVE-2024-38809",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:02b2d849-dd98-54a9-85fa-2de04dbdd292",
      "id": "CVE-2024-38819",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:644f532f-0424-5e43-b679-1001bee23fba",
      "id": "CVE-2024-38820",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38820 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:4c28277f-4ae8-5b24-ae54-93953d3afc29",
      "id": "CVE-2024-38828",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38828 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:96e742bb-aeac-5191-8f99-bc362e50b698",
      "id": "CVE-2025-22233",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-22233 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1e3fcafd-edf3-52c1-9d0f-9e95ec192c71",
      "id": "CVE-2025-41242",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41242 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:5975499a-a8af-58c7-90ff-d8dd13149824",
      "id": "CVE-2025-41249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8161c903-4c50-5b92-95e9-0a0fba098ba6",
      "id": "CVE-2025-41254",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0c6da57-0e9b-5ce5-921c-51ed79e59116",
      "id": "CVE-2026-22740",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-22740 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx. CVE-2026-22740 is a WebFlux-specific vulnerability (reactive multipart temp-file cleanup in org.springframework.http.codec.multipart.MultipartHttpMessageReader / PartGenerator). Spring Framework 4.3.30.RELEASE predates WebFlux entirely - the org.springframework.http.codec package does not exist in this version, and there is no reactive multipart code path. Per NVD, affected versions are 5.3.x, 6.1.x, 6.2.x, 7.0.x only; Spring 4.x is not in the affected range."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:d9f99d99-15db-534a-9f79-423401aafc34",
      "id": "CVE-2026-22741",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22741 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e8e2219b-b68e-5221-b5b0-b3a088e80057",
      "id": "CVE-2026-22745",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1d986e4f-ae6f-5af3-bcc0-a15600b46433",
      "id": "CVE-2026-41838",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41838 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:1f588574-091f-54bb-babc-1d29f9d6c498",
      "id": "CVE-2026-41841",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41841 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:2af6c013-f33d-51d9-ac00-1b48e7d445e5",
      "id": "CVE-2026-41842",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:739567df-b886-51e2-8541-14ba66dec61c",
      "id": "CVE-2026-41843",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:6d632606-4e09-5efa-9d94-6c8958cdc757",
      "id": "CVE-2026-41844",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:014eb093-b00c-5b2c-9c5c-a43650069b97",
      "id": "CVE-2026-41845",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:823bb8b3-ae62-5d69-b3b4-99c388ffc493",
      "id": "CVE-2026-41846",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:3ea45e26-f21f-5330-b506-c55b18cbfeb6",
      "id": "CVE-2026-41848",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:33eb4a66-98ac-5a80-8dcf-36028372fa7e",
      "id": "CVE-2026-41849",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41849 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:0ae57274-d0de-509b-96a8-c44fe792132b",
      "id": "CVE-2026-41850",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:e0ca8206-baac-569b-aa31-0313d22d9c52",
      "id": "CVE-2026-41851",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:ebec187a-11b3-5d37-9a49-af3bcf0c4ed5",
      "id": "CVE-2026-41852",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:8118ed31-6b08-5fd5-b380-7fbeff480c4a",
      "id": "CVE-2026-41853",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41853 does not affect version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx. not_affected \u2014 Spring Framework 4.3.30 is not affected by CVE-2026-41853. This version predates Spring WebFlux (introduced in 5.0) and lacks the vulnerable component DefaultServerWebExchange.java. The vulnerability mechanism - Spring Framework's message reader selection based on wildcard Content-Type headers - does not exist in this servlet-based Spring MVC architecture."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:b89e63a0-55e7-5c6c-b0b6-5e155b074955",
      "id": "CVE-2026-41854",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    },
    {
      "bom-ref": "urn:uuid:61a447d0-fe23-54cc-a659-63703b7d52da",
      "id": "CVE-2026-41855",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41855 affects version 4.3.30.RELEASE-tuxcare.4 of org.springframework:spring-tx."
      },
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
        }
      ]
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-tx@4.3.30.RELEASE-tuxcare.4"
    }
  ]
}